Windows Hello Hardware authenticator vs Windows Hello Software authenticator
289 views
Skip to first unread message
MANIRATHNAM V
unread,
Dec 14, 2023, 5:14:56 AM12/14/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to fido...@fidoalliance.org
I have two windows machine one machine aaguid defined in FIDO MDs data as a Windows Hello Hardware authenticator also attestation type as attca (TPM attestation) and other machine aaguid defined in FIDO MDs data as a Windows Hello Software authenticator also attestation type as basic surrogate (Packed Attestation).my question is in which condition the machines defines as hardware and software authenticator.can anyone please explain this.
Alex Seigler
unread,
Dec 14, 2023, 6:15:06 AM12/14/23
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to MANIRATHNAM V, fido...@fidoalliance.org
My organization has seen the same, specifically since 23H2 update, some machines work fine with TPM attestation as before, others are now giving packed or none attestations without x5c. This is preventing registrations with IdP (Okta) that does
attestation validation against MDS for the Windows Hello Hardware Authenticator aaguid. We have a case open with MSFT for an explanation.
I have two windows machine one machine aaguid defined in FIDO MDs data as a Windows Hello Hardware authenticator also attestation type as attca (TPM attestation) and other machine aaguid defined in FIDO MDs data as a Windows Hello Software authenticator
also attestation type as basic surrogate (Packed Attestation).my question is in which condition the machines defines as hardware and software authenticator.can anyone please explain this.